What the vulnerability does
01Description
Relative Path Traversal vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Eventin: from n/a through <= 4.0.26.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Relative Path Traversal vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Eventin: from n/a through <= 4.0.26.
Explanation of Vulnerability in Simple Terms
Eventin versions up to 4.0.26 contain a path traversal vulnerability that allows unauthenticated attackers to read sensitive files from the server. The vulnerability requires no user interaction and can be exploited over the network. An attacker can access files outside the intended directory structure, potentially exposing configuration files, database credentials, or other confidential data.
What an attacker can do
Read arbitrary files from the server without authentication.
Potential impact on your site
Sensitive files like configuration, credentials, or private data may be exposed to unauthorized parties.
Conditions required to exploit
Network access to the Eventin installation; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities